Microsoft’s July 2026 Patch Tuesday just fixed 570 security flaws — the largest single-month patch release in the company’s history — including two zero-days that attackers were already exploiting in the wild. Counting every other security update Microsoft shipped this month, the real total climbs to 622 CVEs, shattering the record set just one month earlier.
If you run Windows, Windows Server, SharePoint, or Active Directory Federation Services in any capacity, this isn’t a patch cycle to sit out.
The Two Zero-Days Already Under Attack
Two vulnerabilities were being actively exploited before Microsoft shipped a fix, which is the scenario security teams dread most:
- CVE-2026-56155 — a flaw in Active Directory Federation Services (AD FS), the identity backbone many enterprises use for single sign-on. A working exploit here can let an attacker impersonate legitimate users across an entire organization.
- CVE-2026-56164 — a SharePoint Server vulnerability, the same class of on-premise document platform that has been a favorite attacker entry point for years because it’s internet-facing and rarely gets patched fast.
A third flaw, CVE-2026-50661, is a BitLocker security-feature bypass. It’s publicly disclosed but not yet confirmed exploited — which usually means a short window before it is.

Why 59 “Critical” Flaws Matter More Than the Headline Number
570 sounds abstract until you break it down. Microsoft rated 59 of the flaws Critical, and of those, 48 allow remote code execution — meaning an attacker doesn’t need a password, a click, or physical access to run their own code on your machine. The rest of the pile splits into 254 Elevation of Privilege bugs, 145 Remote Code Execution flaws total, 102 Information Disclosure issues, 35 Denial of Service bugs, 17 Security Feature Bypass flaws, and 16 Spoofing vulnerabilities.
Translation: most of these you’ll never think about again after installing the update. The 59 Critical ones — and especially the three flaws above — are the reason “I’ll patch it this weekend” is the wrong call this month.
Why the Number Keeps Climbing
This is the second record month in a row, and it’s not really about Windows getting less secure. According to Microsoft’s own researchers, the spike traces back to AI-assisted vulnerability discovery — both MSRC’s internal tooling and external security researchers are now using AI models to fuzz and audit code at a scale that wasn’t feasible manually. More bugs are being found before criminals find them, which is good news wrapped in an alarming headline. It also means this “record” is unlikely to be the last one this year.
For context, June’s Patch Tuesday was itself a record at the time, with roughly a third of July’s core count. Two consecutive record-breaking months is enough of a pattern that security teams are starting to plan around it rather than treat each one as an outlier — expect patch-management budgets and staffing to shift accordingly through the rest of 2026.
Who’s Actually Affected
The bulk of the 570 flaws touch Windows 10, Windows 11, and Windows Server across every currently supported version, plus Microsoft Office, Edge, .NET, and the two enterprise products named above. Home users on a standard Windows 11 install are exposed mainly through the Elevation of Privilege and Remote Code Execution categories — the kind of bug that turns “clicked a bad link” into “attacker has full control.” Businesses running AD FS or SharePoint Server on-premise carry the sharpest edge of this release, since both are the two actively-exploited zero-days.
What to Do Right Now
If you manage AD FS or SharePoint Server, prioritize those two CVEs today — not at the next scheduled maintenance window. Everyone else should let Windows Update run rather than defer it, especially given the RCE count. If you’re the kind of reader who wants the full step-by-step — how to check your update status, what to do if a reboot fails, and which settings actually control patch timing — our companion guide walks through the whole process.
It’s also a good moment to double-check the hardware side of your security setup. A router still running years-old firmware undermines even a fully patched PC — we tested the current crop of routers if yours predates 2024. And if this record-breaking patch cycle has you eyeing a genuinely fresh machine instead of babysitting an aging one, our budget laptop picks are a reasonable place to start.
Source Attribution
Vulnerability counts and CVE details per Krebs on Security and BleepingComputer’s July 2026 Patch Tuesday coverage; severity breakdown per Microsoft Security Response Center’s own release notes.
Deixe um comentário